Git Product home page Git Product logo

pam_maturity_model's Introduction

Privileged Access Management (PAM) maturity model

created for Identiverse conference, Jun 2018

Level 0 Initial Level 1 Managed Repeatable Level 2 Defined Level 3 Quantitatively Managed Level 4 Optimized
Characteristics No Controls, Unpredictable and reactive Tribe knowledge, often reactive Proactive, Standards documented Measured and controlled, automation Stable and flexible, full automation
Shared password vaulting and management Post-it, spreadsheet, notepad, number of accounts unknown Account inventory with manual rotation Access controls, 2FA, IDM integration RBAC/ABAC, all accounts managed Password-less sessions, configuration management integration
Account discovery accounts unknown, tracked on spreadsheet Manual search of directories and CMDB automated feed from directories automated provisioning for all accounts to vault or credential manager automated tools for directories, fully integrated with config mgt tools
Session Recording None Some privileged sessions recorded and stored Automated searching of recordings All privileged sessions recorded Alerting and integration with your threat dection tools
Account automation and lifecycle None Some accounts automatically provisioned and removed APIs available for all systems to use in automation All accounts automatically provisioned and removed Accounts automatically provisioned with ABAC
Session management and isolation None Some sessions managed Bastion hosts and jumpboxes available for all environments All sessions managed with no passwords exposed to users Required for all segmented networks
Application credential management None Some applications with manual credential managment Most applications are covered Programatic application account managment All applications are in scope and compliant
Privilege account analytics and auditing None Some servers enrolled All critical servers (like domain controllers) are enrolled All servers enrolled Fully integrated with CIRT
Threat detection and automatic response None Some servers enrolled, notifications are sent on issues All servers enrolled All servers enrolled and some threats can be processed automatically Common threats handled automatically and alerts used when needed

pam_maturity_model's People

Contributors

krobert7 avatar

Watchers

James Cloos avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.